Security researchers have found over 35,000 code repositories with malicious forks or clones leading back to a single source. Malware in the tainted code repositories is designed to steal environment variables, stored elements that serve as authentication for various online services.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
76% of ransomware attacks in 2022 were tied to a known vulnerability that was made public between 2010 and 2019, and old vulnerabilities that were discovered as far back as 2015 are still commonly exploited.
Magecart attackers compromised at least 374 e-commerce sites running end-of-life Magento in a day, including planting 19 backdoors on a single website through SQL injection on a vulnerable plugin.
Cyber attack on Toyota's electronics and plastic parts supplier Kojima Industries shut down 28 production lines across 14 plants in Japan, exposing production supply chain vulnerabilities.
The supply chain attack method leverages commonly-used dependency managers and private or non-existent dependencies to install malicious code and backdoors in internal applications.
Russian phishing campaign targets commercial messaging apps, specifically Signal, to steal recovery keys, access historical messages, private and group chats, and take over accounts.
Securing Active Directory credentials is absolutely crucial to protect against network breaches. Access management can help put a protective layer at the forefront of your network.
Vulnerable IT service providers are becoming entry points for supply chain attacks as seen in the recent attack on Wipro. The attack follows closely after Wipro CEO declares "security cannot be a show stopper for business priorities".
Study from HP reveals that nation-state cyber attacks have not only doubled since 2017, but are also increasingly incorporating attacks on physical assets (such as infrastructure).
President Biden’s Executive Order includes a provision that would require software vendors selling to the federal government to maintain a Software Bill of Materials (SBOM). Unfortunately, it’s not that simple.










